[tor-bugs] #6314 [TorBirdy]: prevent leak via Date header field (local timestamp disclosure)

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Dec 18 17:34:44 UTC 2015


#6314: prevent leak via Date header field (local timestamp disclosure)
----------------------+------------------------------
 Reporter:  tagnaq    |          Owner:  ioerror
     Type:  defect    |         Status:  needs_review
 Priority:  High      |      Milestone:
Component:  TorBirdy  |        Version:
 Severity:  Normal    |     Resolution:
 Keywords:            |  Actual Points:
Parent ID:  #9131     |         Points:
  Sponsor:            |
----------------------+------------------------------

Comment (by arthuredelstein):

 To clarify: neither of the patches in comment:19 should necessarily land.
 We are already sanitizing the Date header because of the patch merged in
 comment:18. But because of the tradeoffs I am not sure which is the best
 approach, so I posted the two additional patches here for consideration.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/6314#comment:21>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list